Who We Are
Our website address is: https://www.apachecasinohotel.com. At Apache Casino Hotel, we prioritize the privacy and security pf your personal data, adhering to General Data Protection Regulation (GDPR) and all applicable state laws regarding privacy policies.
What Personal Data We Collect and Why
- Comments: When visitors leave comments on our site, we collect the data shown in the comments form, the visitor’s IP address, and browser user agent string to aid spam detection. An anonymized string from your email address may be used to see if you are using the Gravatar service. After comment approval, your profile picture is visible to the public in the context of your comment.
- Media: Avoid uploading images with embedded location data (EXIF GPS). Visitors can download and extract location data from images on the website.
- Contact Forms & Cookies: If you leave a comment, opt-in to save your name, email, and website in cookies. These are for convenience, so you don’t have to fill in details again for another comment. Cookies will last for one year. We use cookies to manage login information, screen display choices, and for temporary session management. Cookies are also used for users who edit or publish an article, indicating the post ID of the article edited, expiring after 1 day.
- Embedded Content: Articles on this site may include embedded content from other websites, which behaves in the same way as if the visitor has visited the other website.
- Analytics: We collect data for analytics purposes to improve your experience on our website.
- Cell Phone Information: We collect cell phone numbers and related information when you opt into receiving communications from us via text message or when you use our services that require mobile phone interaction. This information is used to send you room keys, promotional items, offers, and to facilitate two-factor authentication and verification of identification processes to enhance the security of your account and our services.
How We Use Your Data
We use your information to provide services requested, communicate with you, and enhance your experience with Apache Casino Hotel. This includes using your information for spam detection, managing comments, and facilitating website interactions.
- Communications: We use programs like Twilio and SlickText to send you text messages for various purposes, including providing room keys, promotional items, important updates, and more. These services help us ensure that our communications are efficient and secure.
- Two-Factor Authentication and Verification: To enhance the security of your transactions and account, we use your cell phone information for two-factor authentication and to verify your identity. This is a crucial step in protecting your personal information and our services from unauthorized access.
Who We Share Your Data With
We do not share your personal information with third parties, except as necessary for our services or as required by law. This includes internal departments, our advertising firm, and external service providers under confidentiality agreements. Visitor comments may be checked through an automated spam detection service.
- Service Providers: We share your cell phone information with trusted third-party service providers, such as Twilio and SlickText, which facilitate our text messaging services. These providers are carefully selected and obligated to handle your information in line with our privacy standards and GDPR requirements.
How Long We Retain Your Data
Comments and their metadata are retained indefinitely for follow-up comments. For users that register, personal information in their user profile is stored indefinitely and can be seen, edited, or deleted by the user (username cannot be changed) and website administrators.
Your Rights
You have the right to access, correct, delete, or restrict the use of your personal information. This includes requesting an exported file of personal data we hold about you and requesting the erasure of your personal data, with exceptions for data kept for legal, administrative, or security purposes.
Data Security
We implement robust security measures to protect your information and have data breach procedures in place to manage potential risks.
Additional Information
How We Protect Your Data
Our commitment to data security is unwavering. We employ a variety of security measures designed to protect your personal information from unauthorized access, alteration, disclosure, or destruction. These include, but are not limited to, encryption technologies, secure server infrastructure, and internal policies governing data access. Our staff is trained on the importance of privacy and how to handle and secure your personal information properly.
- Partner Programs: In our use of third-party services like Twilio and SlickText, we ensure that all partners adhere to stringent data protection standards and provide detailed information with audit reports annually. Contracts with these partners include clauses that enforce the confidentiality and security of your data, require annual audits of their security around your data, alongside GDPR compliance.
Data Breach Procedures
In the unlikely event of a data breach, we have a comprehensive response plan designed to promptly assess the situation, contain the impact, and protect our users’ data. This includes immediate investigation, notification to affected individuals in accordance with applicable laws, and collaboration with law enforcement and data protection authorities as necessary. We also review and update our security measures and practices to prevent future breaches.
Third Parties
We receive data from third parties only when it is essential for our services or when it enhances the functionality of our website. This may include data from analytics providers, advertising networks, and service functionalities that improve user experience. We rigorously assess the privacy policies of these third parties to ensure their practices align with our privacy standards before engaging in any data exchange.
- Usage of Third-Party Services: We utilize third-party services for enhanced communication and security measures, including sending text messages, two-factor authentication, and verification of identification. We conduct thorough vetting to ensure these services comply with our privacy standards and GDPR requirements before integration.
Automated Decision Making and Profiling
We may use automated decision-making processes to improve your experience or manage our services more efficiently. This could include, for example, algorithms that suggest products or services based on your browsing behavior or previous purchases. Any automated decision-making that we use is designed with your privacy in mind, ensuring that it is fair, transparent, and limited in scope. You have the right to request human intervention or challenge decisions made about you through automated processes.
Contact Us for More Information
If you have any questions about the protection of your data, our data breach procedures, how we interact with third parties, our use of automated decision-making, or our compliance with industry-specific regulations, please do not hesitate to contact us at [email protected]. We are dedicated to transparency and are here to provide any clarifications you may need.
Opt-Out Instructions
You have the option to opt-out of data processing activities by following the instructions provided on our website or as directed in our communications.
- Cell Phone Communications: To stop receiving the text messages from our services which will remove offers, communications on room status, room key on the phone, and other services, reply to the text with the word “STOP”.
- Email Communications: Click the link to be removed from the email received.
Contact Our Data Protection Officer
For inquiries about our privacy practices, contact our Data Protection Officer at [email protected].
Responding to Legal Requests
We may disclose data to law enforcement or legal requests in compliance with the law, ensuring the protection of our users’ privacy.
Cross-Border Data Flows
We comply with GDPR requirements for cross-border data flows to protect and maintain the integrity of your personal data.
Automated Decision Making and Profiling
We may use automated decision-making for service personalization, with safeguards to ensure fairness and transparency.
International Data Transfers
If data is transferred internationally, we take steps to ensure it receives protection equivalent to that provided by GDPR.
Legal Basis for Processing
Our processing of your data is based on consent, contract performance, legal obligations, and our legitimate interests.
Children’s Privacy
We do not knowingly collect data from children without parental consent and adhere to the relevant children’s privacy laws.
Updates to the Privacy Policy
We will notify you of any significant updates to our policy and obtain your consent where necessary.